It would be extremely useful to be able to filter and search for EDR agents based on any and all meta data fields available for the agent.
This is a fairly basic feature and is something almost every major EDR vendor has (SentinelOne, Defender for Endpoint, Crowdstrike, ect..) and would love to see Huntress have it too
As it currently is only being able to search by agent name or SN is very limiting in both asset management and visibility during incidents/recovery.
Example:
Say there is an incident detected where the SOC has sent out org wide isolation, but the client has multiple un-connected remote locations that are later confirmed unimpacted, out of scope of the incident, or low risk of further impact upon further review of the incident (Especially if reviewed by a DFIR firm brought in through cyber insurance). It would be useful to be able to quickly search for all the endpoints at those remote locations by external IP or tag (if you are adding site tags on agent install) and release isolation so the client can resume some operation faster at those remote locations while the rest of the recovery at main locations is still under way.